| Process injection |
Process 2060 manipulating memory of non-child process 1336 |
| Process injection |
Process 2060 manipulating memory of non-child process 1384 |
| Process injection |
Process 2060 manipulating memory of non-child process 1424 |
| Process injection |
Process 2060 manipulating memory of non-child process 2072 |
| Process injection |
Process 2060 manipulating memory of non-child process 2940 |
| Process injection |
Process 2060 manipulating memory of non-child process 2132 |
| Process injection |
Process 2060 manipulating memory of non-child process 2764 |
| Process injection |
Process 2060 manipulating memory of non-child process 732 |
| Process injection |
Process 2060 manipulating memory of non-child process 2060 |
| Process injection |
Process 2060 manipulating memory of non-child process 3360 |
| Time & API |
Arguments |
Status |
Return |
Repeated |
1619987929.433124
NtAllocateVirtualMemory
|
process_identifier:
1336
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000134
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00350000
|
success
|
0 |
0
|
1619987930.152124
NtAllocateVirtualMemory
|
process_identifier:
1384
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000001cc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00130000
|
success
|
0 |
0
|
1619987930.496124
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000134
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x06c30000
|
success
|
0 |
0
|
1619987930.746124
NtAllocateVirtualMemory
|
process_identifier:
2072
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000134
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00120000
|
success
|
0 |
0
|
1619987930.918124
NtAllocateVirtualMemory
|
process_identifier:
2940
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000134
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00140000
|
success
|
0 |
0
|
1619987931.089124
NtAllocateVirtualMemory
|
process_identifier:
2132
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000001cc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x000f0000
|
success
|
0 |
0
|
1619987931.105124
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000134
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x003c0000
|
success
|
0 |
0
|
1619987931.105124
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000001cc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x001f0000
|
success
|
0 |
0
|
1619987931.277124
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000001cc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x03e40000
|
success
|
0 |
0
|
1619987931.277124
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000001cc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x04610000
|
success
|
0 |
0
|
1619987941.558124
NtAllocateVirtualMemory
|
process_identifier:
1336
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000274
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02730000
|
success
|
0 |
0
|
1619987941.558124
NtAllocateVirtualMemory
|
process_identifier:
1384
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000278
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02160000
|
success
|
0 |
0
|
1619987941.558124
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000274
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x027c0000
|
success
|
0 |
0
|
1619987941.574124
NtAllocateVirtualMemory
|
process_identifier:
2072
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000278
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01ee0000
|
success
|
0 |
0
|
1619987941.574124
NtAllocateVirtualMemory
|
process_identifier:
2940
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000274
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x000f0000
|
success
|
0 |
0
|
1619987941.574124
NtAllocateVirtualMemory
|
process_identifier:
2132
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000278
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00120000
|
success
|
0 |
0
|
1619987941.589124
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000274
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x003e0000
|
success
|
0 |
0
|
1619987941.589124
NtAllocateVirtualMemory
|
process_identifier:
3360
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000274
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x002d0000
|
success
|
0 |
0
|